T09 · Insecure Skill Coding Practices
- Location
scripts/jin10_mcp.py:20- Finding
Hard-Coded Jin10 Bearer Token
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its news-and-market monitoring purpose, but it embeds shared Jin10 credentials and copied tracking cookies that users should review before installing.
Review this skill before installing if you are uncomfortable with shared embedded provider credentials or fixed browser tracking identifiers being sent to Jin10. Use it only for its intended news and market-data reporting workflow, and avoid providing extra secrets beyond the documented provider API keys needed for market data.
scripts/jin10_mcp.py:20Hard-Coded Jin10 Bearer Token
scripts/telegraphs.py:116Hard-Coded Tracking Cookie and Persistent Device Identifier
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
if elapsed < 12:
time.sleep(12 - elapsed)
response = requests.get(url, timeout=30)
cls._last_request_time = time.time()
cls._request_count += 1
The skill hard-requires Chinese output regardless of the user's preference, which overrides user autonomy and can violate platform language-policy expectations. In practice, this can cause the agent to ignore or mishandle user requests made in other languages, reducing usability and potentially obscuring important safety-critical details for users who cannot read Chinese.
The file-level documentation says this script is a simplified Jin10 MCP client for independently fetching quotes and flash news, implying it is a self-contained Jin10 utility. However, during MCP initialization the code reports clientInfo.name as 'iran-war-tracker-skill', which contradicts that stated identity and intent. This is an active documentation/intent mismatch rather than a mere omission.
This code file contains user-facing natural language entirely in Chinese, including the module description and later printed test output, with no indication that language choice is configurable or intentionally limited to a Chinese-only audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.
The entire template is written in Chinese and structures the skill output exclusively in that language. Under the policy, a skill should not force a specific language or locale unless it offers opt-in or clearly documents a justified regional constraint, which this file does not do.
The instruction '默认用中文输出' forces a specific language behavior in natural-language guidance. Under the policy, locale or language constraints should either be user-selectable or clearly justified as region-specific; this file provides neither.
Natural-language instructions and descriptions in this file are exclusively Chinese, including the primary module docstring and usage guidance. Under the stated policy, forcing a specific language without opt-in can be a locale-policy issue when no alternative language or explicit justification is provided.
This code performs outbound HTTP requests to Alpha Vantage using requests.get, which transmits query parameters including the API key and usage metadata to an external service. Although network access is central to the script's purpose, there is no explicit user-facing notice at runtime or nearby warning comment disclosing that external services are contacted and credentials from environment variables are used.
The call to pandas.read_csv with a remote HTTPS URL fetches data from a third-party service, but the script does not clearly warn users that backup mode causes additional outbound requests to Stooq. This is a user-disclosure gap because the operation reaches outside the local environment and may not be obvious from the invocation interface alone.
The Jin10 request hard-codes an Accept-Language header preferring zh-CN, zh, and related locales. This is a natural-language policy concern because it imposes a specific language/locale choice in behavior without offering the user any option to select or override it.
No suspicious patterns detected.